CVE-2017-1000250
bluez: Out-of-bounds heap read in service_search_attr_req function
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.
Todas las versiones del servidor SDP en BlueZ 5.46 y anteriores son vulnerables a sufrir una divulgación de información que permite que los atacantes remotos obtengan información sensible de la memoria del proceso bluetoothd. Esta vulnerabilidad se basa en el procesamiento de peticiones del atributo de búsqueda SDP.
An information-disclosure flaw was found in the bluetoothd implementation of the Service Discovery Protocol (SDP). A specially crafted Bluetooth device could, without prior pairing or user interaction, retrieve portions of the bluetoothd process memory, including potentially sensitive information such as Bluetooth encryption keys.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-09-12 CVE Reserved
- 2017-09-12 CVE Published
- 2017-11-12 First Exploit
- 2024-08-05 CVE Updated
- 2024-08-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-125: Out-of-bounds Read
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://nvidia.custhelp.com/app/answers/detail/a_id/4561 | X_refsource_confirm | |
http://www.securityfocus.com/bid/100814 | Third Party Advisory | |
https://access.redhat.com/security/vulnerabilities/blueborne | Not Applicable | |
https://www.kb.cert.org/vuls/id/240311 | Third Party Advisory | |
https://www.synology.com/support/security/Synology_SA_17_52_BlueBorne | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://github.com/olav-st/CVE-2017-1000250-PoC | 2017-11-12 | |
https://www.armis.com/blueborne | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3972 | 2018-02-17 | |
https://access.redhat.com/errata/RHSA-2017:2685 | 2018-02-17 | |
https://access.redhat.com/security/cve/CVE-2017-1000250 | 2017-09-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1489446 | 2017-09-12 |